Hopefully you listened when I said get your resumes ready. @GreyNoiseIO is hiring Threat Researchers who will develop and exploit first, second, and third-party access and sources to produce cyber threat intelligence that practitioners will use to detect, disrupt, and impose cost on adversaries. https://t.co/bh6V84K6SN
@ImposeCost I typically call the narrowing variety of post-exploitation TTPs the “technique funnel” where adversaries eventually need to be on the same platform as the final objective (e.g. cloud email theft, you’ve gotta at some point take mail).
Good model for post-compromise detection ROI
@ItsReallyNick When I think about that quietly to myself, I think do I want to defend at every door, or put a machinegun in hallway that every door feeds to. But I would never say that publicly.
@ItsReallyNick When I think about that quietly to myself, I think do I want to defend at every door, or put a machinegun in hallway that every door feeds to. But I would never say that publicly.
I think that all of the focus on exploit specific detection is a losing strategy in general. Post-exploitation detection is more resilient and if you're strong there, you will catch intrusions regardless of the CVE number. The overwhelming majority of in the wild zero day exploitation I have encountered in my life has been identified by detecting post-exploitation behavior.
This is so much more true now that the deluge of CVEs has created a scenario where the whole industry is trying to figure out if badness is attributable to this CVE versus that CVE when in two weeks another batch of CVEs will be released for that technology, some that the detectable characteristics will match previous CVEs, some that won't, but the post-exploitation behavior will remain largely unchanged.
Please see our latest Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778. Citrix urges affected customers to install the relevant updated versions as soon as possible. https://t.co/0JS7KidPd8
I feel bad for anyone who is going to make life altering decisions based on the hot takes of AI thought leaders. General population is very susceptible to influence.
@AmmarAshshiddi1 I feel like overcoming the mitigations is part of the challenge in a way. Then it's about how good you are at building the capability. I don't know. I think it the competitive nature helps breed a better cyber talent pool, great.
That's the real value of CTFs.
I haven't done CTFs in a long time. However, I'm a big proponent of them, because often they should present you with challenges you haven't been exposed to before and require you to solve a novel to you problem, and therefore learn things. AI can help you learn, and I like learning with AI. I would hate to just point AI at a CTF to win without learning.
@OffZeroCyber I'm not sure I've subscribed to all of the extreme takes from AI thought leaders. They've continued to say stupid shit.
As for whether I'm willing to bet the house on not needing any of these skills, I am not.
Police found roughly 30 partially clothed young men packed inside a sweltering basement at a Wisconsin fraternity house, covered in food, condiments and other liquids — with several showing signs of being physically struck.
Officers responded to an anonymous tip at the Alpha Epsilon Pi house on Langdon Street in Madison around 8:20 p.m. Wednesday during rush week. The thermostat in the basement was set to 81 degrees, creating hot and humid conditions. The vast majority of those inside were 18 years old.
Fraternity president Brayden J. Klein and vice president Samuel N. Vane, both 20, were arrested on hazing and disorderly conduct allegations. Police say cooperation from those at the scene was limited, and statements from witnesses didn't align — raising red flags for investigators.
Full story here https://t.co/arIQKuEMGK
Can't realistically do it for everything, but when I see an LLM do something I don't know how to do that I think matters, I take a bit of time to learn how to do it by hand. Both to be better, and to prove that it's not totally hallucination.
I know this gets debated a lot lately, but it’s cool watching models and harnesses absolutely lay waste to CTFs. At the same time, I think there’s something being lost in speed running all of it.
A lot of these CTFs humans walk away from with little 1–2% things they learned along the way. None of it seems huge at the time, but you stack enough of those reps over a career and eventually you’re able to stitch them together when you run into something weird.
The real world is still messy. Brute force and speed are awesome until you hit something that requires novel thinking and there isn’t a clean path to the answer.